GNU gzexe Temporary File Command Execution Vulnerability
BID:10603
Info
GNU gzexe Temporary File Command Execution Vulnerability
| Bugtraq ID: | 10603 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2004-0603 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jun 24 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | The individual responsible for discovery of this issue is currently unknown; this issue was disclosed in the referenced Gentoo advisory. |
| Vulnerable: |
GNU gzip 1.3.3 |
| Not Vulnerable: | |
Discussion
GNU gzexe Temporary File Command Execution Vulnerability
Reportedly gzexe is affected by a temporary file command execution vulnerability. This issue is due to a failure of the application properly handle exceptional condition when attempting to create temporary files.
This issue may allow an attacker to execute an arbitrary file in the context of an unsuspecting user; this may potentially lead to privilege escalation or unauthorized access.
Reportedly gzexe is affected by a temporary file command execution vulnerability. This issue is due to a failure of the application properly handle exceptional condition when attempting to create temporary files.
This issue may allow an attacker to execute an arbitrary file in the context of an unsuspecting user; this may potentially lead to privilege escalation or unauthorized access.
Exploit / POC
GNU gzexe Temporary File Command Execution Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
GNU gzexe Temporary File Command Execution Vulnerability
Solution:
Gentoo has released advisory GLSA 200406-18 dealing with this issue. It is recommended that all users using the affected software upgrade using the following sequence of commands:
# emerge sync
# emerge -pv ">=app-arch/gzip-1.3.3-r4"
# emerge ">=app-arch/gzip-1.3.3-r4"
Additionally, once the upgrade is complete, all self-extracting files created with earlier versions gzexe should be recreated, since the vulnerability is actually embedded in those executables. Please see the referenced Gentoo advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Gentoo has released advisory GLSA 200406-18 dealing with this issue. It is recommended that all users using the affected software upgrade using the following sequence of commands:
# emerge sync
# emerge -pv ">=app-arch/gzip-1.3.3-r4"
# emerge ">=app-arch/gzip-1.3.3-r4"
Additionally, once the upgrade is complete, all self-extracting files created with earlier versions gzexe should be recreated, since the vulnerability is actually embedded in those executables. Please see the referenced Gentoo advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
GNU gzexe Temporary File Command Execution Vulnerability
References:
References:
- GNU Homepage (GNU)
- gzip home page (GNU)